Impact
A use‑after‑free bug in the GPU subsystem of Google Chrome can be triggered by a crafted HTML page, allowing a remote attacker to execute arbitrary code outside the browser sandbox. The flaw is the classic CWE‑416 weakness and carries a CVSS score of 9.6, indicating a severe vulnerability that can compromise confidentiality, integrity, and availability of the host system.
Affected Systems
The issue affects Google Chrome desktop releases older than 154.0.8037.57. Users running any pre‑154 version are vulnerable, regardless of operating system, as the fault lies in the browser’s GPU processing code.
Risk and Exploitability
The CVSS score of 9.6 reflects the high exploitation potential and broad impact of this bug. Although no EPSS data is reported, the absence of a KEV listing does not diminish the likelihood of exploitation by attackers who construct malicious HTML content. Attackers would likely deliver the payload via a web page accessed from a remote host; the vulnerability is exploitable in a purely client‑side context, making it convenient for widespread attacks.
OpenCVE Enrichment
Debian DSA